CISA published an advisory on September 29, 2026 describing two high-severity vulnerabilities in the Lantronix G520 Series Cellular Gateway that it said could allow an attacker to replace software and execute arbitrary code with root privileges. The agency said version 2.6.0.4R6_stable of the G520 Series is affected.
What CISA found
The advisory covers CVE-2026-84409, an issue tracked as improper neutralization of input during web page generation (cross-site scripting, CWE-79), and CVE-2026-91191, an improper verification of cryptographic signature issue (CWE-347). Both carry a CVSS v3.1 base score of 7.5 and a CVSS v4.0 base score of 7.7, rated HIGH.
For CVE-2026-84409, CISA said the device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use, after which a management interface returns the stored value in a JSON response and the web interface inserts it directly into the page as HTML. According to the advisory, that lets attacker-controlled metadata be interpreted as script content, while the same authenticated origin provides an interface capable of executing system-level commands with root privileges.
For CVE-2026-91191, CISA said the boot process disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed, and that the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation, the advisory said.
Who is affected
CISA listed the affected critical infrastructure sectors as Transportation Systems, Energy, and Water and Wastewater Systems. The devices are deployed worldwide, and Lantronix is headquartered in the United States, according to the advisory.
CISA credited Ievgen Bondarenko with reporting the vulnerabilities, and said no known public exploitation specifically targeting them has been reported to the agency at this time.
Fix and mitigations
CISA said Lantronix has addressed the reported issues with release version 2.6.0.7R6, which is available on the company's website. The advisory also points readers to the Lantronix Vulnerability Library and to Lantronix support for further information.
Beyond the vendor fix, CISA repeated its standard defensive guidance for control system devices, including minimizing network exposure, placing devices behind firewalls and isolating them from business networks, and using more secure remote access methods such as VPNs while recognizing that VPNs themselves may have vulnerabilities. The agency also urged organizations to perform impact analysis and risk assessment before deploying defensive measures, and to avoid clicking links or opening attachments in unsolicited email.
What to do
- Update affected Lantronix G520 Series gateways to firmware release 2.6.0.7R6, available on the Lantronix website.
- Consult the Lantronix Vulnerability Library or contact Lantronix support at Support@lantronix.com for more information or technical assistance.
- Minimize network exposure for control system devices and ensure they are not accessible from the internet.
- Place control system networks and remote devices behind firewalls and isolate them from business networks.
- Where remote access is needed, use more secure methods such as VPNs, keeping them updated and recognizing a VPN is only as secure as the connected devices.
- Perform impact analysis and risk assessment before deploying defensive measures, and report suspected malicious activity to CISA.
- Avoid clicking web links or opening attachments in unsolicited email messages to reduce social engineering risk.
Key facts and where they come from
- Exploitation could allow software replacement and root-level code execution.
Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.
- Affected version is G520 Series 2.6.0.4R6_stable.
G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191)
- Both flaws score 7.5 on CVSS v3.1, rated HIGH.
3.1
7.5
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - Lantronix released fixed firmware 2.6.0.7R6.
Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website.
- The SDK exposes the production private key trusted by firmware builds.
the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds
- No known public exploitation has been reported to CISA.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
- Ievgen Bondarenko reported the vulnerabilities.
Ievgen Bondarenko reported these vulnerabilities to CISA.
